Get a Pentest and security assessment of your IT network.

Cyber Security

Windows zero-day with bad patch gets new public exploit code

Microsoft released a fix for a vulnerability in the Windows operating system that enabled attackers to increase their permissions to kernel level on a compromised machine. The original bug was an arbitrary pointer dereference allowing an attacker to control the src and dest pointers to a memcpy function. Microsoft s patch in June did not fix the original vulnerability (CVE-2020-0986) and it can still be leveraged with some adjustments. Microsoft’s patch was improper because it changed the pointers to offsets, so the function’s parameters could still be controlled.

Source: https://www.bleepingcomputer.com/news/security/windows-zero-day-with-bad-patch-gets-new-public-exploit-code/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security